Greetings, we have recently implemented the Active Directory Group, Protected Users. It is recommended by Microsoft to put all Domain Admin accounts into this group, including our account used by PRTG for accessing WMI on monitored servers. After the PRTG account is moved however, access to things like drive space monitoring, stop working and report Access is Denied. Once the account is removed from that group everything works fine. Could you please explain how we can work around this and keep that account in the Protected Users group?
Domain Admin account and Protected Users Group
Modified on 2025-06-10 14:55:39 +0200
Disclaimer:
The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.
The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.
HI there,
Please note that WMI access rights are not well documented by Microsoft and therefore I cannot say which certain access rights are required. However, I would recommend to give the corresponding user access do DCOM and WinRM since it's used for WMI.
Aug, 2021 - Permalink